MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e61c559d005c75640aa4c96f500dbb1fab046505ecc017448736ac96690ced13. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 5
| SHA256 hash: | e61c559d005c75640aa4c96f500dbb1fab046505ecc017448736ac96690ced13 |
|---|---|
| SHA3-384 hash: | 10f475b309b096547059425c252890ed3597bbc6137ecd04730214c62373e4e287c411e969a2a7bbb8265bdbb369613b |
| SHA1 hash: | 863cd4f44833684b7be1f24f4d1019d0f38d31ae |
| MD5 hash: | 3e7cd1cfab54fd8ea79b7610d6baab2b |
| humanhash: | magazine-washington-pizza-bacon |
| File name: | 677809.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 365'316 bytes |
| First seen: | 2023-01-11 12:39:59 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:ckzbNPm5onk7iuETKOZJF2xxBnhk7uEssPbYkdLbfXizSVfttShd9h0hUTisup7:ldPion83OZJ6nhKFzYkdLbfl5vS7BTRW |
| TLSH | T16A742244D72C9508BC82971E917CAB39E4AFE56AA90919EFEE05F4C5D30FC48D70E4E8 |
| TrID | 80.0% (.ZIP) ZIP compressed archive (4000/1) 20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1) |
| Reporter | |
| Tags: | AgentTesla INVOICE zip |
cocaman
Malicious email (T1566.001)From: ""CEO" <helena.kraft@serva.com>" (likely spoofed)
Received: "from hosted-by.rootlayer.net (unknown [45.137.22.170]) "
Date: "11 Jan 2023 10:51:48 +0100"
Subject: "Top Urgent Due/Unpaid Invoices"
Attachment: "677809.zip"
Intelligence
File Origin
File Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | 677809.exe |
|---|---|
| File size: | 555'002 bytes |
| SHA256 hash: | 25483a164b2ab3cb283f494f2022793b99595bbf3af41b0620dcd3b0d3d612be |
| MD5 hash: | 7416af0e6dbe13b36bdfe2e609b00666 |
| MIME type: | application/x-dosexec |
| Signature | AgentTesla |
Vendor Threat Intelligence
Result
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
AgentTesla
zip e61c559d005c75640aa4c96f500dbb1fab046505ecc017448736ac96690ced13
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.